Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 373 respecto a la semana anterior
Críticas / altas1323▲ 43 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.54% | — | Soarkey StudentmanagementAI | 14/9/2026 | 14/9/2026 | A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. Affected is the function RegisterServlet.doPost of the file code/WebContent/register.html of the component Registration Workflow. Such manipulation of the argument level leads to improper privilege management.… | |
| Aplazada | Media (5.5) | 0.52% | — | Soarkey StudentmanagementAI | 31/8/2026 | 31/8/2026 | A weakness has been identified in Soarkey StudentManagement and 学生信息管理系统 up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. This impacts the function AdminDao.doGet of the file code/src/service/AdminDao.java of the component Administrative Servlet. Executing a manipulation of the argument action can lead to authorization… | |
| Aplazada | Baja (2.1) | 0.33% | — | Soarkey StudentmanagementAISoarkey XueshengxinxiguanlixitongAI | 31/8/2026 | 1/9/2026 | A security flaw has been discovered in Soarkey StudentManagement and 学生信息管理系统 up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. This affects the function CourseDao.course_ranking of the file code/src/dao/CourseDao.java. Performing a manipulation of the argument cno results in sql injection. It is possible to initiate… | |
| Aplazada | Baja (2.1) | 0.45% | — | Hemant6488 Codeigniter StudentmanagementsystemAI | 26/5/2026 | 23/7/2026 | A vulnerability was identified in hemant6488 CodeIgniter-StudentManagementSystem. The impacted element is the function addStudent of the file view_students.php of the component Students Controller. The manipulation of the argument Name leads to cross site scripting. The attack is possible to be carried out remotely.… | |
| Aplazada | Media (5.5) | 0.47% | — | Hemant6488 Codeigniter-studentmanagementsystemAI | 26/5/2026 | 23/7/2026 | A vulnerability was determined in hemant6488 CodeIgniter-StudentManagementSystem. The affected element is an unknown function of the file /index.php/students/addStudentView of the component Student Management Handler. Executing a manipulation can lead to improper access controls. The attack can be executed remotely.… | |
| Aplazada | Media (5.5) | 0.41% | — | Yashpokharna2555 StudentmanagementsystemAI | 25/5/2026 | 23/7/2026 | A vulnerability was found in yashpokharna2555 StudentManagementSystem up to cb2f558ddf8d19396de0f92abf2d224d46a0a203. Affected by this issue is the function confirm_logged_in of the file /studentdel.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has… | |
| Aplazada | Baja (2) | 0.33% | — | Yashpokharna2555 StudentmanagementsystemAI | 25/5/2026 | 23/7/2026 | A vulnerability was detected in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. This impacts an unknown function of the file /student.php. Performing a manipulation of the argument FIRST_NAME results in cross site scripting. The attack can be initiated remotely. The exploit is now… | |
| Aplazada | Media (5.5) | 0.41% | — | Yashpokharna2555 StudentmanagementsystemAI | 25/5/2026 | 23/7/2026 | A security vulnerability has been detected in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. This affects the function confirm_logged_in of the file student_trans.php. Such manipulation of the argument FIRST_NAME/Last_Name/EMAIL leads to sql injection. It is possible to launch the… | |
| Aplazada | Media (5.5) | 0.41% | — | Yashpokharna2555 StudentmanagementsystemAI | 25/5/2026 | 23/7/2026 | A weakness has been identified in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. The impacted element is an unknown function of the file /success.php. This manipulation of the argument User causes sql injection. It is possible to initiate the attack remotely. The exploit has been… |